MEDIUM
chamilo
CVE published 2026-09-11
CVE-2026-82535
CVE-2026-82535 is a stored cross-site scripting vulnerability in Chamilo LMS before 1.11.42 and 3.0.0. Unauthenticated attackers can inject malicious script payloads into survey answers, which are then rendered in reporting views, potentially executing arbitrary scripts in the browser sessions of teachers or administrators. This vulnerability allows attackers to bypass authorization checks in the survey s [truncated]